馃 PoP Zero is my homelab
README.md

maintenance #

Backup of /mnt/Cofrin to an S3-compatible bucket using restic. Runs at 06:00 and 18:00.

Deploy to the cluster:

kubectl apply -f apps/maintenance/

One-off secret creation from host .env:

kubectl create secret generic backup-env \
  --namespace=maintenance \
  --from-env-file=/mnt/Cofrin/backup/.env

All backups are client-side encrypted by restic (AES-256). The .env file must contain RESTIC_REPOSITORY (e.g. s3:https://<endpoint>/<bucket>), RESTIC_PASSWORD, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY.

On failure the program sends a message to a Nextcloud Talk conversation via a bot. NEXTCLOUD_TALK_SECRET (bot shared secret) and NEXTCLOUD_TALK_TOKEN (conversation token from the URL /call/{token}) must be in the .env file. NEXTCLOUD_URL is set in the CronJob manifest.

Databases are dumped with dedicated tools (pg_dump, mariadb-dump, sqlite3 .backup) before each snapshot. Dump configs live in apps/maintenance/dbs.yaml and reference the database .env files on the host directly (no credential duplication). Raw database files are excluded from the snapshot; the dumps are part of it.